google-flights

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Anomaly
AnomalyLOW
.github/workflows/publish.yml

This is a standard CI/CD publishing workflow with no direct evidence of intentional malware in the YAML itself. The dominant supply-chain risk is that it downloads and runs the ClawHub CLI from npm during the workflow without pinning/verifying the CLI version or integrity; a compromised CLI could execute arbitrary code in CI and misuse the provided authentication token. Secondary concerns include publishing all repository files from `.` without explicit inclusion controls and embedding the raw last commit message into published changelog metadata (possible secret leakage if present in commit messages).

Confidence: 70%Severity: 60%
Audit Metadata
Analyzed At
Apr 13, 2026, 08:23 AM
Package URL
pkg:socket/skills-sh/skillhq%2Fflight-search%2Fgoogle-flights%2F@49ed0d291fef933d52e3722e1e99ec710786f01d